# Logstash pull data from Event Hub And output to several LogAnalytics

**URL:** <https://discuss.elastic.co/t/logstash-pull-data-from-event-hub-and-output-to-several-loganalytics/213813>\
**Category:** Logstash\
**Created:** [January 5, 2020, 5:10pm UTC](https://discuss.elastic.co/t/logstash-pull-data-from-event-hub-and-output-to-several-loganalytics/213813 "2020-01-05T17:10:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![omrip](https://avatars.discourse-cdn.com/v4/letter/o/a9adbd/32.png) [@omrip](https://discuss.elastic.co/u/omrip)\
**Post date:** [January 5, 2020, 5:10pm UTC](https://discuss.elastic.co/t/logstash-pull-data-from-event-hub-and-output-to-several-loganalytics/213813/1 "2020-01-05T17:10:13Z")

</div>

Hi,  
i am trying to send data from 2 pipelines inputs of Eventhub and forward the data to 2Log Analytics instances.  
there are 2 configuration file to read data from each event hub.  
the output of the data is send to 2 Log analytics each.  
Event hub 1 -----\>data is send to Main LA and to EventHub1-LA instance  
Event hub 2 -----\>data is send to Main LA and to EventHub2-LA instance  
i do not want the L\>A  
when ruuning the pipe line the data is mixed and being sent to to all an different LA analytics instances .

here are the conf. files:

input {  
azure\_event\_hubs {  
event\_hub\_connections =\> ["Endpoint=\<this is Event hub 1"]  
threads =\> 3  
decorate\_events =\> true  
consumer\_group =\> "$Default"

}  
}  
filter {  
if "beats\_input\_codec\_plain\_applied" in [tags] {  
mutate {  
remove\_tag =\> ["beats\_input\_codec\_plain\_applied"]  
}  
}

```
    }

```

output {  
azure\_loganalytics {  
customer\_id =\> "main Log Analytics"  
shared\_key =\> xxxxxxxxxx  
log\_type =\> "Syslog"  
time\_generated\_field =\> "iso8610timestamp"  
key\_names =\> ['cloud','message','winlog','instance','agent','host','tags']  
key\_types =\> {'cloud'=\>'string' 'message'=\>'string' 'winlog'=\>'string' 'instance'=\>'string' 'tags'=\>'string' agent=\>'string' host=\>'string'}  
flush\_items =\> 10  
flush\_interval\_time =\> 5  
}

```
    azure_loganalytics {
    customer_id => "resource group of event hub 1 "
    shared_key => "xxxxxxxxxx"
    log_type => "Syslog"
    time_generated_field => "iso8610timestamp"
    key_names => ['cloud','message','instance','winlog','agent','host','tags']
    key_types => {'cloud'=>'string' 'message'=>'string' 'winlog'=>'string' 'instance'=>'string' 'tags'=>'string' agent=>'string' host=>'string'}
     flush_items => 10
    flush_interval_time => 5

```

}  
}

input {  
azure\_event\_hubs {  
event\_hub\_connections =\> ["Endpoint=this is event Hub 2"]  
threads =\> 3  
decorate\_events =\> true  
consumer\_group =\> "$Default"

}  
}  
filter {  
if "beats\_input\_codec\_plain\_applied" in [tags] {  
mutate {  
remove\_tag =\> ["beats\_input\_codec\_plain\_applied"]  
}  
}

```
    }

```

output {  
azure\_loganalytics {  
customer\_id =\> "this is the main Azure Log Analytics"  
shared\_key =\> "xxxxxxxxxx"  
log\_type =\> "Syslog"  
time\_generated\_field =\> "iso8610timestamp"  
key\_names =\> ['cloud','message','winlog','instance','agent','host','tags']  
key\_types =\> {'cloud'=\>'string' 'message'=\>'string' 'winlog'=\>'string' 'instance'=\>'string' 'tags'=\>'string' agent=\>'string' host=\>'string'}  
flush\_items =\> 10  
flush\_interval\_time =\> 5  
}

```
 azure_loganalytics {
	customer_id => "this is resource group 2"
	shared_key => "xxxxxxxxxxxx"
	log_type => "Syslog"
	time_generated_field => "iso8610timestamp"
	key_names => ['cloud','message','instance','winlog','agent','host','tags']
	key_types => {'cloud'=>'string' 'message'=>'string' 'winlog'=>'string' 'instance'=>'string' 'tags'=>'string' agent=>'string' host=>'string'}
	flush_items => 10
	flush_interval_time => 5

```

}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2020, 5:10pm UTC](https://discuss.elastic.co/t/logstash-pull-data-from-event-hub-and-output-to-several-loganalytics/213813/2 "2020-02-02T17:10:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
